Ask most people why an organisation runs open-source software and they will tell you it's cheaper. For the clients we work with, cost is almost the least interesting reason — and treating it as the headline gets the whole decision wrong.
For a government department, a defence supplier, or a firm holding data that could end careers if it leaked, the question is not “what is the cheapest way to be secure?” It is “who controls the systems that protect us, and can we prove it?” That is a sovereignty question, and open source answers it in a way proprietary platforms structurally cannot.
What sovereignty actually requires
Consider what sovereignty actually requires. First, that you can inspect the software protecting you — not take its behaviour on trust, but read how detection, filtering, and hardening work. Second, that you can host it where your legal and operational obligations require, not where a vendor's architecture happens to put it. Third, that you can keep it running without any single company's permission, pricing decision, or geopolitical exposure.
Proprietary security fails at least one of these by design. Open foundations satisfy all three.
Why we build the way we do
This is why we build Cairn's services on Wazuh, Zabbix, pfSense, Ansible, and GLPI. Not because they are free — our clients pay for expertise, operation, and accountability regardless — but because they are auditable and ownable.
When a client's auditor asks how a detection fires, we don't say “the vendor scores it.” We show them the rule. When a board asks what happens if the relationship with Cairn ends, the honest answer is: you keep the platform and take it in-house. That is a sovereignty guarantee, and it is only possible on open foundations.
The savings are a side effect
The cost savings are real, but they are a side effect. The reason to choose open source for critical systems is that it is the only model where control genuinely stays with you. In a world where “where is our data, and who can see it?” has become a board-level and national-security question, that control is the entire value.
None of this makes open source a religion. Where a genuine requirement is better met by a proprietary component, we say so and integrate it. But the default runs the other way for a reason: sovereignty is a property you build in from the foundations, not one you bolt on later.